Remote control system for medical devices based on Internet of Things data

By adopting multi-source data acquisition, baseline model construction, real-time abnormality detection, risk grading evaluation and adaptive security strategy execution methods in the remote control system of medical equipment, the problem that existing systems are difficult to achieve flexible real-time identification and dynamic security protection when facing complex abnormal situations is solved, efficient security protection is achieved, and the stability and security of medical equipment are ensured.

CN119916667BActive Publication Date: 2025-06-20ANNING FIRST PEOPLES HOSPITAL +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510409153.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-06-20
Estimated Expiration
2045-04-02

AI Technical Summary

Technical Problem

When existing remote control systems for medical equipment are faced with complex and multi-dimensional abnormal situations, it is difficult to achieve flexible real-time identification and dynamic security protection, which affects the controllability and reliability of remote control of medical Internet of Things.

Method used

Through four links: multi-source data acquisition and behavior baseline construction, real-time abnormality detection, risk grading assessment and linkage processing, and adaptive security strategy implementation, efficient security protection for remote control of medical equipment is achieved. Specific steps include: collecting and cleaning the operation logs, building a baseline model; calculating instruction deviations in real time, filtering suspicious instructions; performing multi-factor risk scores, filtering medium and high-risk instructions; calculating strategy priorities based on risk vectors, and implementing security measures.

Benefits of technology

It realizes efficient and safe protection for remote control of medical equipment, improves the system's ability to adapt to complex scenarios, promptly identify and deal with abnormal operating behaviors, and ensures patient safety and stable operation of equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119916667B_ABST
    Figure CN119916667B_ABST
Patent Text Reader

Abstract

The present invention discloses a remote control system for medical devices based on Internet of Things data, which relates to the technical field of device remote control. Through four links of multi-source data collection and behavior baseline construction, real-time anomaly detection, risk classification assessment and linkage processing, and adaptive security policy execution, efficient and secure protection for the remote control of medical devices is realized. First, the operation logs are collected and cleaned, and multi-dimensional tags are added to construct a baseline model M to determine the deviation degree. Subsequently, the deviation degree of the instructions is calculated in real time, and the suspicious instructions are screened to form a structured set of suspicious instructions. In the risk classification stage, multi-factor scoring is performed on the suspicious instructions, and medium and high-risk objects are screened. Finally, the policy priority is calculated based on the risk vector and matched with the predefined interval, and security protection is implemented through measures such as multi-factor authentication, secondary approval or temporary freezing, and the disposal results are continuously written back and updated to form a closed loop to improve the overall security control level.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of equipment remote control, and in particular to a medical equipment remote control system based on Internet of Things data. Background Art

[0002] With the widespread penetration of IoT technology in the medical industry, various types of intelligent medical equipment have gradually realized networking, dataization and remote management, helping hospitals improve resource utilization efficiency and provide patients with more timely and accurate diagnosis and treatment services. In existing applications, key medical equipment such as infusion pumps, monitors, imaging equipment and surgical assistance robots are often connected to hospital information systems through wireless networks or wired private networks, and interconnected with remote terminals or mobile devices to achieve cross-regional operations and data exchange. However, medical scenarios often involve different departments, medical staff at different levels and diversified clinical processes. There are also differences in models and functional complexity between devices. In addition, the dynamic changes in patients' conditions and the uncertainty of the network environment make remote control and real-time monitoring processes face higher security and reliability challenges. Although the remote control architecture based on IoT data can significantly improve the efficiency of diagnosis and treatment, how to ensure the accuracy and security of data transmission and the compliance of operation processes while maintaining high availability of equipment has become an important issue that needs to be solved in the current deepening of medical IoT applications.

[0003] In the Chinese invention patent with the authorization announcement number CN118534832B, a medical equipment remote control method and system are disclosed, which includes the following steps: collecting real-time operating parameters of remote medical equipment, collecting data through sensors, screening key parameters of temperature, power consumption and response time, identifying abnormal data points through preset thresholds, and generating a key operating parameter abnormality list. In the present invention, sensors are used to comprehensively monitor key operating parameters and actively identify abnormalities, timely discover potential problems of medical equipment and allow rapid intervention, prevent small problems from turning into major failures, not only ensure that medical equipment continues to operate in the optimal state, but also through in-depth analysis of equipment adjustment logs, accurate performance evaluation records are made, and operations are further optimized. By implementing data-based decisions, remote operation standards and protocols are updated to ensure the high quality and safety of medical services, especially the response speed and efficiency when dealing with acute diseases and emergency medical situations.

[0004] How to identify and handle possible abnormal operation behaviors in real time and with high precision when remotely controlling medical devices. Specifically, medical devices often involve multi-dimensional data collection and control instructions, including patient physiological parameters, device operating status, clinical usage scenarios, etc. During the process of network transmission and cross-system docking, these data are extremely likely to lead to misjudgment due to delays, poor synchronization, data inconsistency, or lack of context information. Once medical staff or external systems issue abnormal instructions to the device (such as sudden large-scale parameter modifications, unauthorized personnel operating the device during non-working hours, etc.), if they cannot be detected and corresponding measures are not taken in time, it may pose serious risks to patient safety or the stable operation of the device. Currently, the general monitoring mechanisms mostly stay at the level of simple threshold alarms or event tracking based on fixed rules, and it is difficult to achieve flexible real-time identification and dynamic security protection when complex and multi-dimensional changes occur, thus bringing greater potential hazards to the controllability and reliability of remote control in the medical Internet of Things.

[0005] For this reason, the present invention provides a remote control system for medical devices based on Internet of Things data. Summary of the Invention

[0006] (I) Technical problems to be solved

[0007] Aiming at the deficiencies of the prior art, the present invention provides a remote control system for medical devices based on Internet of Things data. Through four links: multi-source data collection and behavior baseline construction, real-time anomaly detection, risk grading assessment and linkage processing, and adaptive security policy execution, it realizes efficient and secure protection for the remote control of medical devices. First, collect and clean operation logs, add multi-dimensional tags, and construct a baseline model M to determine the deviation degree; then, calculate the deviation degree of the instructions in real time, screen out suspicious instructions and form a structured set of suspicious instructions; in the risk grading stage, perform multi-factor scoring on the suspicious instructions and screen out medium and high-risk objects; finally, calculate the policy priority according to the risk vector and match the predefined interval, implement security protection through measures such as multi-factor authentication, secondary approval, or temporary freezing, and continuously write back and update the disposal results to form a closed loop to improve the overall security management level, thereby solving the technical problems described in the background art.

[0008] (II) Technical solutions

[0009] To achieve the above objectives, the present invention is realized through the following technical solutions: A remote control system for medical devices based on Internet of Things data collects operation logs of medical devices, removes duplicates and validates fields to form a cleaned log data set, adds tags and performs normalization processing to generate a preprocessed log data set, statistically analyzes the distribution of each dimension and uses Rényi divergence to determine the degree of deviation, and writes the results into the baseline model M;

[0010] Receive the original data stream of real-time instructions and align them to generate real-time instruction data, calculate the deviation from the baseline model M, determine suspicious or normal instructions and output them to the labeled instruction result set, screen suspicious instructions and encapsulate them into a structured suspicious instruction set, realizing multi-dimensional and highly sensitive anomaly recognition;

[0011] Read the structured suspicious instruction set and supplement the context to synthesize a temporary data set, perform multi-factor risk scoring on each suspicious instruction, generate a risk scoring output result, screen medium and high-risk instructions to obtain a risk linkage processing output object, and notify the administrator or start the linkage process according to the scoring result;

[0012] Obtain medium and high-risk instructions from the risk linkage processing output object, form a temporary risk instruction data set, calculate the priority based on the risk vector and match the predefined interval, output to the policy mapping output object, and execute the corresponding security measures according to the policy mapping output object.

[0013] Furthermore, read each log record in the cleaned log data set and add operation role tags, instruction type tags, and time segment tags to it;

[0014] Perform normalization mapping on the logs containing numerical fields and store the new values in additional fields; add hierarchical tags to each record and output the final preprocessed log data set. Based on the established medical process and historical experience, create an empty baseline model M with a multi-dimensional distribution structure.

[0015] Furthermore, respectively count the actual frequency distributions for each key dimension from the preprocessed log data set, denoted as , and use the Renyi divergence to compare the difference between the reference distribution and .

[0016] If the value of the dimension exceeds the sensitivity threshold, write as the new reference distribution into the baseline model M, otherwise maintain the original reference distribution unchanged, where

[0017] ;

[0018] In the formula: is the actual frequency value of a certain operation mode under the dimension, is the corresponding frequency of the reference distribution under the same dimension, is the sensitivity control parameter, is the set of all possible values of the dimension.

[0019] Furthermore, conduct a preliminary consistency check on each field in the original data stream of real-time instructions and align it with the required dimensions of the baseline model M. If there are missing or abnormal fields, mark the record with a field anomaly flag but still retain its core information;

[0020] Extract each instruction from the aligned real-time instruction data , locate its affiliated role, time period, instruction type, the corresponding reference center vector m and sensitivity factor parameters in M.

[0021] Furthermore, define a collaborative anomaly formula to measure the deviation degree of the instruction from the reference center vector m as follows:

[0022] ;

[0023] where is the numerical feature of the current instruction on key dimensions, is the reference center value vector in the baseline model M, is the sensitivity factor of the dimension, and are power coefficients, : collaborative anomaly amplification coefficient;

[0024] If the deviation degree , mark the instruction as suspicious; otherwise, consider it normal, store the judgment result in the labeled instruction result set A1, and attach the value and the suspicious or normal label to each instruction; for the instructions marked as normal, only write them into the ordinary operation log for future reference and do not trigger the subsequent high-intensity risk assessment process.

[0025] Furthermore, read all the instruction sets determined to be suspicious from the structured suspicious instruction set, parse out the target fields, and summarize them into a temporary data set; if any suspicious instruction in the structured suspicious instruction set lacks the necessary fields, mark the field as missing in the temporary data set;

[0026] Based on the information such as the device type, the department to which the operator belongs, and the current diagnosis and treatment link of each suspicious instruction in the temporary data set, query the internal clinical context database to supplement the environmental factors.

[0027] Furthermore, the baseline model M or the configuration center reads the risk-related weight set , amplification coefficient and several non-linear parameters (such as , after numerically expressing the feature vector z of each suspicious instruction in the temporary dataset, the following risk score is defined :

[0028] ;

[0029] where: z is a multi-dimensional feature vector, is the numerical expression of the th risk factor, is the weight factor, is the non-linear amplification coefficient of the single factor, is the aggregation coefficient, is the non-linear parameter, used to control the impact of the collaborative product term on the overall risk;

[0030] If , it is recorded as low risk; if , it is recorded as medium risk; if , it is recorded as high risk. The risk score and risk level of each suspicious instruction are packaged into a new object risk score output result, and the necessary context backtracking information is also saved.

[0031] Furthermore, filter out the instructions with medium or high risk levels in the risk score output result, and further determine whether it is necessary to immediately notify the medical supervisor or security administrator. For the instructions marked as low risk, only audit retention is performed, and they do not enter the mandatory security policy process; for the suspicious instructions with medium or high risk, their core information is encapsulated into the risk linkage processing output object, and the current server timestamp is attached to trigger the notification or the intervention of the security administrator in a timely manner.

[0032] Furthermore, merge to form a temporary risk instruction dataset, and the record contains at least the following fields: risk score S, risk level and emergency flag U; divide the records in the temporary risk instruction dataset T4 into medium risk group and high risk group, and retain the value of U. If the record is an emergency scenario, mark it with an emergency priority flag;

[0033] Combine the key elements of each record into a vector , and define the following priority , and evaluate the final policy strength by integrating multi-dimensional features:

[0034] ;

[0035] where: is 's -norm, usually taking to represent the Euclidean length, is used to gradually accumulate the risk from 0 to amplify the process then measure the collaborative lifting effect of each component are all control coefficients greater than 0 is the identity matrix of the corresponding dimension.

[0036] Furthermore, after calculating the priority compare the result with several pre-defined intervals. If the priority , follow the low-intensity protection process, additional identity verification or warning reminder; if , follow the medium-intensity protection process, multi-factor authentication, high-intensity approval process;

[0037] If the priority , follow the high-intensity protection process, temporarily freeze the operation, force a secondary approval, or allow the operation in an emergency scenario but record and audit the whole process; write the final priority of each record and the selected policy mapping result into the policy mapping output object.

[0038] (III) Beneficial effects

[0039] The present invention provides a remote control system for medical devices based on Internet of Things data, having the following beneficial effects:

[0040] 1. Through multi-source data collection and baseline model construction, a reference standard for subsequent anomaly detection is successfully established, providing a quantifiable benchmark for real-time monitoring and accurate identification; screening out unqualified data in advance and multi-dimensionally annotating legal data lay a solid foundation for subsequent real-time or batch detection and analysis, improving the system's adaptability to complex scenarios.

[0041] 2. The use of the non-linear deviation formula can provide a more sensitive detection ability when there are multi-dimensional anomalies in the operation characteristics; it can also promptly detect small but continuous deviations. After determining whether the instruction is suspicious or normal, the suspicious instruction will be further encapsulated immediately, shortening the transmission cycle of the suspicious information from detection to subsequent response, and achieving more timely risk isolation.

[0042] 4. Output the detection results in a structured manner, retaining key fields such as the operator, timestamp, deviation degree, etc., which is not only convenient for the risk assessment module in the third step to quickly read, but also convenient for subsequent analysis. Only log the normal instructions, improving the overall processing efficiency, concentrating the main calculations and resources on more risky suspicious instructions, and improving the resource utilization rate.

[0043] 5. Through the combined scoring of multi-dimensional factors (such as roles, anomaly types, clinical scenarios, etc.), the operational risk is quantified more precisely, no longer limited to a single indicator. Mapping the scoring results to low, medium, and high grades, and combining with the threshold strategies preset by third parties or in-house experts, suspicious instructions can be quickly classified into different risk levels for subsequent differential processing.

[0044] 6. Through the refined risk assessment and hierarchical disposal of suspicious instructions, the one-size-fits-all processing method is avoided, and precise and hierarchical security management is achieved. In addition to improving the recognition accuracy of abnormal risks, it also provides complete context and hierarchical information for the subsequent execution of security policies, ensuring that security measures are more targeted and feasible.

[0045] 7. Different security measures are taken according to different risk levels and urgencies. On the one hand, it reduces the interference to the normal operation of the hospital, and on the other hand, it strictly prevents extreme or malicious operation events. The disposal information can be traced and audited throughout the process, and the actual disposal results are applied to the subsequent upgrade and iteration of the system itself, continuously improving the overall security control level. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 It is a schematic flow chart of the remote control system for medical devices based on Internet of Things data of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0047] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0048] Please refer to Figure 1 , the present invention provides a remote control system for medical devices based on Internet of Things data, including,

[0049] Step 1: Collect the operation logs of medical devices, remove duplicates and verify the fields to form a cleaned log data set, add tags and perform normalization processing to generate a preprocessed log data set, statistically analyze the distributions of each dimension and use the Rényi divergence to determine the deviation degree, and write the results into the baseline model M;

[0050] The content of the said Step 1 includes the following:

[0051] Step 101: Obtain various operation logs through the log interface, remove duplicate records, and verify the integrity of fields. The output result is the cleaned log data set D1. If serious format errors or missing key fields are found, mark the corresponding records as abnormal; read each log record in the cleaned log data set D1, and add operation role tags (such as doctor, nurse), instruction type tags (such as equipment adjustment, access query), and time period tags (such as working hours, night shift) to generate the preprocessed log data set D2;

[0052] For logs containing numerical fields (such as network latency, operation frequency), perform normalization mapping in the preprocessed log data set D2. To reduce the impact of extreme values on subsequent analysis, logarithmic mapping or interval mapping is used, and the new numerical values are stored in additional fields;

[0053] Add department or section-level tags to each record to distinguish the operation differences of different medical functional groups in the future. After this process, the final preprocessed log data set D2 is output, providing dimensionally cleaned and labeled data for subsequent baseline model construction;

[0054] When in use, by performing deduplication and field verification on the original log data, duplicate records can be effectively removed and obvious format errors can be captured, improving the accuracy and completeness of subsequent analysis data. Mark and retain abnormal or missing information separately to ensure that protective measures or supplementary corrections can be taken according to this mark in subsequent links, thereby reducing missed detections or misdetections caused by source data problems. Adding multiple tags (role, instruction type, time period, etc.) to each log record can more accurately characterize operation behavior features in subsequent dimensional analysis and avoid missing important information. Using a normalization algorithm to map numerical fields can alleviate the interference of extreme values on the overall statistical model and make the subsequent baseline model more stable in diverse clinical and operating environments.

[0055] Step 102: Based on established medical procedures and historical experience, create an empty baseline model M with a multi-dimensional distribution structure (role - time period - instruction type - department);

[0056] Statistically calculate the actual frequency distributions for each key dimension (such as role, time period, instruction type, department) from the preprocessed log data set D2, denoted as , and to enhance the sensitivity of identifying distribution differences, use the Rényi divergence in the following formula to compare the difference between the reference distribution (derived from historical statistics) and :

[0057] ;

[0058] In the formula: is the The actual frequency value of a certain operation mode under a dimension is the corresponding frequency of the reference distribution under the same dimension, is the sensitivity control parameter, with a value greater than 1, is the set of all possible values of the th dimension. The larger this divergence is, the more obvious the deviation of the current distribution from the historical reference baseline; If the value of a certain dimension

[0059] exceeds the sensitivity threshold, will be written as the new reference distribution into the baseline model M, otherwise the original reference distribution remains unchanged. In this way, the baseline can be updated in time when the medical working mode changes, ensuring that the determination of abnormal operations is more timely. Finally, the updated baseline model M is obtained, and the distribution calculation results and relevant thresholds are archived for the next real-time anomaly detection to determine the deviation degree of new operation instructions; When in use, by calculating the statistical distributions of different dimensions and judging the deviation degree based on advanced metrics (such as Rényi divergence), it can flexibly adapt to the changes in operation modes in medical scenarios and improve the sensitivity to abnormal trends; the generated behavior baseline model records the reference distribution information in multiple dimensions. Once a significant deviation occurs in subsequent operations, it can quickly determine whether there are potential risks or anomalies, greatly reducing the burden of manual inspections.

[0060] When in use, combine the content in steps 101 and 102: Through multi-source data collection and baseline model construction, a reference standard for subsequent anomaly detection has been successfully established, providing a quantifiable benchmark for real-time monitoring and accurate identification; screening out unqualified data in advance and performing multi-dimensional annotation on legal data lay a solid foundation for subsequent real-time or batch detection and analysis, improving the system's adaptability to complex scenarios.

[0061] Step 2: Receive the original data stream of real-time instructions and align to generate real-time instruction data, calculate the deviation degree from the baseline model M, determine suspicious or normal instructions and output them to the labeled instruction result set, and screen out suspicious instructions and encapsulate them into a structured suspicious instruction set to achieve multi-dimensional and highly sensitive anomaly recognition;

[0062] The said step 2 includes the following content:

[0063]

[0064] ​Step 201: Receive a real-time instruction stream from an external operation source and converge it into the original data stream R0 of real-time instructions. Each record contains (timestamp, operator ID, instruction type, terminal information, etc.). Conduct a preliminary consistency check on each field in the original data stream R0 of real-time instructions and align it with the required dimensions (role, time period, department, etc.) of the baseline model M to generate the aligned real-time instruction data R1. If there are missing or abnormal fields, mark the record with a field anomaly flag but still retain its core information.

[0065] When in use, quickly align the newly arrived operation instruction data with the fields required by the baseline model M to reduce the recognition delay or error caused by inconsistent formats and ensure that the data can be directly used for deviation calculation. Mark the records with missing or abnormal fields to ensure that such incomplete data can be flexibly processed in subsequent detections and risk assessments, rather than simply discarded or ignored.

[0066] Step 202: Extract each instruction from the aligned real-time instruction data R1 , and locate the corresponding reference center vector m and sensitivity factor and other parameters in M for its belonging role, time period, and instruction type

[0067] Define a collaborative anomaly formula to measure the deviation of the instruction from the reference center vector m , where not only the deviation in a single dimension is accumulated, but also the detection of the multi-dimensional collaborative effect is introduced through a product term. The method is as follows:

[0068] ;

[0069] where is the numerical feature of the current instruction on key dimensions, is the reference center value vector in the baseline model M, is the sensitivity factor of the dimension, which is used to adjust the contribution of this dimension to the overall deviation, and are power coefficients, with values greater than 1, to enhance the penalty for outliers and multi-dimensional anomalies, : Collaborative anomaly amplification coefficient, with a value greater than 1. When deviations occur in multiple dimensions simultaneously, this product term will significantly amplify , improving the sensitivity to compound anomalies, is used to constrain possible extremely large values and ensure the numerical stability of the deviation result; Compare with the deviation threshold saved in the baseline model M;

[0070] If the deviation , mark this instruction as suspicious; otherwise, consider it normal. At the same time, the baseline model M is allowed to set multiple thresholds (such as ), so as to perform more refined risk grading subsequently; store the judgment result in the labeled instruction result set A1, and attach value and suspicious or normal label to each instruction;

[0071] When in use, the non-linear deviation formula can provide more sensitive detection ability when there are multi-dimensional anomalies in the operating characteristics; small but continuous deviations can also be detected in a timely manner. After determining whether the instruction is suspicious or normal, the suspicious instruction will be further encapsulated immediately, shortening the transmission cycle of suspicious information from detection to subsequent response, and realizing more timely risk isolation.

[0072] Step 203: Screen all the instructions marked as suspicious from the labeled instruction result set A1, and encapsulate them together with their keywords such as role and time period into the structured suspicious instruction set A2. For the instructions marked as normal, only write them into the ordinary operation log for future reference, and no longer trigger the subsequent high-intensity risk assessment process. The structured suspicious instruction set A2 (including suspicious instructions and related contexts) will be sent to the third step of risk grading assessment and linkage processing for the risk assessment module to comprehensively determine the risk level and execute the corresponding security policies;

[0073] When in use, the detection results are output in a structured manner, retaining keywords such as the operator, timestamp, and deviation degree, which is not only convenient for the risk assessment module in the third step to quickly read, but also convenient for subsequent analysis. Only log the normal instructions to improve the overall processing efficiency, and concentrate the main calculations and resources on the more risky suspicious instructions to improve the resource utilization rate.

[0074] When in use, combine the content in Steps 201 to 203: Identify potential suspicious behaviors in real time and efficiently, which can not only issue risk warnings at the stage of operation occurrence, but also lay an information foundation for subsequent in-depth risk assessment. Through the multi-dimensional deviation calculation method, the adaptability to complex abnormal scenarios is greatly improved, and the dependence on a single threshold or simple rules is reduced.

[0075] Step Three: Read the structured suspicious instruction set and supplement the context to synthesize a temporary data set, perform multi-factor risk scoring on each suspicious instruction, generate a risk scoring output result, screen the medium and high-risk instructions to obtain the risk linkage processing output object, and notify the administrator or start the linkage process according to the scoring result;

[0076] The above Step Three includes the following content:

[0077] Step 301: Read all the sets of instructions determined to be suspicious from the structured suspicious instruction set A2, parse the target fields (operator ID, role category, instruction type, deviation value, etc.), and summarize them into a temporary data set C3; if any of the suspicious instructions in the structured suspicious instruction set A2 is missing necessary fields (such as role information, time period label), mark the missing fields in the temporary data set C3 for reference in subsequent decision-making;

[0078] Based on the information such as the device type, the department to which the operator belongs, and the current diagnosis and treatment link of each suspicious instruction in the temporary data set C3, query the internal clinical context database to supplement environmental factors (such as the patient's condition level, whether the device is in a critical usage stage, etc.). This process packages the context elements of each suspicious instruction into the extended fields of C3, enabling each instruction to have multi-dimensional feature descriptions (role, device criticality, clinical importance, etc.); if a situation where necessary information cannot be obtained occurs during the synthesis process, retain a null value in C3 and attach an exception mark;

[0079] When in use, while reading the suspicious instructions, supplement the clinical or business context (such as device type, department information, patient's condition status), which can make the subsequent risk score more in line with medical reality, explicitly mark the instructions lacking key fields, provide a higher fault tolerance rate for subsequent grading and linkage, and reduce misjudgment or missed judgment.

[0080] Step 302: The baseline model M or the configuration center reads the weight set related to risks , amplification factor and several non-linear parameters (such as , it should be noted that these parameters are predefined by the security administrator or clinical experts according to different business scenarios and device types, aiming to reflect differential sensitivity in multi-dimensional abnormal scenarios;

[0081] To characterize the combined risk effect among multiple factors, after numerically expressing the feature vector z of each suspicious instruction in the temporary data set C3, define the following risk score :

[0082] ;

[0083] In the formula: z is the multi-dimensional feature vector extracted from C3 (such as operator role sensitivity, device criticality, deviation, clinical importance, etc.), is the numerical expression of the th risk factor (for example, the quantization value of role sensitivity), is the weight factor, measuring the importance of the th risk factor relative to the whole, is the non-linear amplification factor of a single factor, with a value greater than 1, is the aggregation coefficient for overall power amplification of the weighted sum of all factors. It takes a value greater than 1, which can improve the recognition of overall risks when multiple factors are simultaneously high. is the non-linear parameter for power processing of each factor in the product term. It takes a value greater than 1. is used to control the impact of the collaborative product term on the overall risk. It takes a value greater than 1, and the larger the value, the more emphasis is placed on the common increase of multi-dimensional risk factors.

[0084] Calculate the risk score After that, compare it with multiple configured scoring thresholds (such as , , ).

[0085] If , it is recorded as low risk; if , it is recorded as medium risk; if , it is recorded as high risk.

[0086] Pack the risk score and risk level of each suspicious instruction into the new object risk score output result R2. The risk score output result R2 also stores necessary context backtracking information (such as operator ID, device identifier, timestamp) to ensure the feasibility of subsequent auditing and tracking.

[0087] Through the combined scoring of multi-dimensional factors (role, anomaly type, clinical scenario, etc.) and by attaching customizable amplification coefficients and synergy effect parameters, the operational risk can be quantified more precisely and is no longer limited to a single indicator. Mapping the scoring results to low, medium, high, etc. levels and combining with the threshold strategy preset by third-party or in-hospital experts can quickly classify suspicious instructions into different risk levels for subsequent differential processing.

[0088] Step 303: Screen out the instructions with medium or high risk levels in the risk score output result R2, and further determine whether it is necessary to immediately notify the medical supervisor or security administrator. For the instructions marked as low risk, only audit records are kept and they do not enter the mandatory security policy process.

[0089] For suspicious instructions with medium or high risk, encapsulate their core information (such as instruction identifier, risk score, risk level, context data) into the risk linkage processing output object R3, and attach the current server timestamp.

[0090] For medium and high risk instructions, it can promptly trigger notifications or the intervention of security administrators, and integrate and output the instruction context to the next step, reducing information loss during the transmission process. Only audit records are made for low risk instructions, focusing resources on handling higher risk events and improving overall efficiency.

[0091] During use, in combination with the content in Steps 301 to 303: By conducting refined risk assessment and hierarchical disposal of suspicious instructions, a one-size-fits-all approach is avoided, achieving precise and hierarchical security management. In addition to improving the accuracy of identifying abnormal risks, it also provides complete context and hierarchical information for subsequent security policy execution, ensuring that security measures are more targeted and feasible.

[0092] Step Four: Obtain medium and high-risk instructions from the output object of risk linkage processing, form a temporary risk instruction dataset, calculate the policy priority based on the risk vector and match the predefined interval, output to the policy mapping output object, and execute corresponding security measures according to the policy mapping output object;

[0093] The said Step Four includes the following content:

[0094] Step 401: Read all suspicious instructions determined to be medium or high risk from the risk linkage processing output object R3, merge them to form a temporary risk instruction dataset T4, and the record contains at least the following fields: risk score S, risk level and emergency flag U; if some records in the risk linkage processing output object R3 are missing necessary fields, make a data anomaly mark for them in the temporary risk instruction dataset T4, and adopt a protective strategy in the subsequent execution link (such as defaulting to a higher-level approval or freezing process);

[0095] Divide the records in the temporary risk instruction dataset T4 into a medium-risk group ), and a high-risk group , and retain the value of U. If the record is an emergency scenario ( ), then mark it with an emergency priority flag, which may trigger a special processing path in the subsequent policy stage; distinguish emergency scenarios in the preliminary screening to prepare for possible emergency priority channels or more stringent control during subsequent policy decision-making, and mark potential data anomalies at this time to prevent unexpected conflicts or omissions during the policy execution stage.

[0096] Step 402: Combine the key elements of each record into a vector , which are respectively represented as: : Risk score, the higher the value, the higher the potential threat; : Risk level, 1 for medium risk, 2 for high risk, : Emergency flag, 1 indicates an emergency scenario, 0 indicates a normal scenario; define the following priority , and evaluate the final policy strength by integrating multi-dimensional features:

[0097] ;

[0098] In the formula: is The -norm is often taken as to represent the Euclidean length. It is used to amplify the process of gradually accumulating risk from 0 to . Then it measures the collaborative uplift effect of each component. Both are control coefficients greater than 0 and can be adjusted in the system configuration file. is the identity matrix for the corresponding dimension.

[0099] After calculating the priority , compare the result with several predefined intervals.

[0100] If the priority , follow the low-intensity protection process, additional identity verification or warning reminder.

[0101] If , follow the medium-intensity protection process, multi-factor authentication, high-intensity approval process.

[0102] If the priority , follow the high-intensity protection process, temporarily freeze the operation, enforce secondary approval, or allow the operation in an emergency scenario but record and audit the whole process.

[0103] Write the final priority of each record and the selected policy mapping result into the policy mapping output object S4, retaining the key fields (such as the selected policy name, policy strength level, etc.).

[0104] When in use, it can evaluate the risk vector more flexibly, fully reflecting the collaborative amplification or hierarchical attenuation characteristics of multi-dimensional information, map the calculation result to the predefined policy interval, quickly retrieve the corresponding security protection plan, such as multi-factor authentication, secondary approval, temporary freeze or emergency release, etc., to avoid policy inconsistencies caused by fuzzy retrieval. Take differentiated security measures for different risk levels and emergency degrees. On the one hand, reduce the interference to the normal operation of the hospital, and on the other hand, strictly prevent extreme or malicious operation events. The whole process realizes the traceability and auditability of the disposal information, and applies the actual disposal result to the subsequent upgrade and iteration of the system itself, continuously improving the overall security control level.

[0105] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0106] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments, and will not be described herein again.

[0107] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only for some logical function divisions. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of devices or units can be electrical, mechanical, or other forms.

[0108] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0109] As described above, this is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in this application, and all should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. A remote control system for medical equipment based on IoT data, characterized by: include, Collect medical equipment operation logs, remove duplicates and verify fields to form a cleaned log data set, add labels and normalize to generate a log preprocessing data set, count the distribution of each dimension and use Rényi divergence to determine the degree of deviation, and write the results into the baseline model M; Receive the original data stream of real-time instructions and align them to generate real-time instruction data, calculate the deviation from the baseline model M, determine suspicious or normal instructions and output them to the label instruction result set, filter suspicious instructions and encapsulate them into a structured suspicious instruction set to achieve multi-dimensional and highly sensitive anomaly recognition; define the collaborative anomaly formula to measure the deviation S(x) between the instruction x and the reference center vector m, as follows: Where x=(x1,…,x n ) is the numerical feature of the current instruction in n key dimensions, m=(m1,…,m n ) is the reference center value vector in the baseline model M, λ i is the sensitivity factor of the i-th dimension, β and γ are power coefficients, η: collaborative anomaly amplification coefficient; wherein, the collaborative anomaly formula is defined to measure the deviation S(x) between instruction x and the reference center vector m. If the deviation S(x)>θ, the instruction is marked as suspicious; otherwise, it is considered normal, and the judgment result is stored in the label instruction result set A1, and the S(x) value and the suspicious or normal label are added to each instruction; for instructions marked as normal, they are only written into the ordinary operation log for reference, and no longer trigger the subsequent high-intensity risk assessment process; Read the structured suspicious instruction set and supplement the context to synthesize a temporary data set, perform multi-factor risk scoring on each suspicious instruction, generate risk scoring output results, screen medium and high risk instructions to obtain risk linkage processing output objects, and notify the administrator or start the linkage process based on the scoring results; Obtain medium and high risk instructions from the risk linkage processing output object, form a temporary risk instruction data set, calculate the policy priority based on the risk vector and match the predefined interval, output to the policy mapping output object, and execute corresponding security measures based on the policy mapping output object;.

2. The medical equipment remote control system based on Internet of Things data according to claim 1, characterized in that: Read each log record in the cleaned log data set and add operation role labels, instruction type labels, and time segment labels to it; Perform normalization mapping on logs containing numeric fields and store new values ​​in additional fields; add hierarchical labels to each record, output the final log preprocessing dataset, and create an empty baseline model M based on established medical processes and historical experience, which contains a multi-dimensional distribution structure.

3. The medical equipment remote control system based on Internet of Things data according to claim 2 is characterized in that: The actual frequency distribution of each key dimension is counted from the log preprocessing data set, denoted as Px, and the Rényi divergence is used to compare the reference distribution R i With P i The difference If the dimension D σ (P i ||R i ) value exceeds the sensitivity threshold, P i Write the baseline model M as the new reference distribution, otherwise keep the original reference distribution unchanged, where Where: P i (x) is the actual frequency value of a certain operation mode x in the i-th dimension, R i (x) is the corresponding frequency of the reference distribution in the same dimension, σ is the sensitivity control parameter, and Ω is the set of all possible values ​​of the i-th dimension.

4. The medical equipment remote control system based on Internet of Things data according to claim 3 is characterized in that: Perform a preliminary consistency check on each field in the raw data stream of the real-time instruction and align it with the dimensions required by the baseline model M. If a missing or abnormal field is found, the record will be marked with a field abnormality but its core information will still be retained; Take each instruction x from the aligned real-time instruction data, locate its role, time period, instruction type, the corresponding reference center vector m and sensitivity factor λ in M i parameter.

5. The medical equipment remote control system based on Internet of Things data according to claim 4 is characterized in that: Read all instruction sets that are determined to be suspicious from the structured suspicious instruction set, parse out the target fields, and summarize them into a temporary data set; if any suspicious instruction in the structured suspicious instruction set is missing a required field, mark it as missing in the temporary data set; Based on the device type, operator department, and current diagnosis and treatment information of each suspicious instruction in the temporary data set, the internal clinical context database is queried to supplement environmental factors.

6. The medical equipment remote control system based on Internet of Things data according to claim 5, characterized in that: The baseline model M or the configuration center reads the risk-related weight set {ω i }, amplification factor η and several nonlinear parameters, after numerically expressing the feature vector z of each suspicious instruction in the temporary data set, the following risk score Risk(z) is defined: Where: z is a multidimensional feature vector, F i (z) is the numerical expression of the i-th risk factor, ω i is the weight factor, α is the nonlinear amplification coefficient of a single factor, β is the aggregation coefficient, γ is the nonlinear parameter, and η is used to control the impact of the synergistic product term on the overall risk; If Risk(z)<θ L , recorded as low risk; if θ L ≤Risk(z)<θ M , recorded as medium risk; if Risk(z)≥θ M , recorded as high risk, and the risk score and risk level of each suspicious instruction are packaged into the new object risk score output result, and the necessary context traceback information is also saved.

7. The medical equipment remote control system based on Internet of Things data according to claim 6, characterized in that: In the risk scoring output results, instructions with medium or high risk levels are screened out, and further judgment is made as to whether it is necessary to notify the medical supervisor or security administrator immediately. For instructions marked as low risk, they are only retained for audit and do not enter the mandatory security policy process. For suspicious instructions with medium or high risk, their core information is encapsulated into the risk linkage processing output object, and the current server timestamp is attached to trigger notification or security administrator intervention in a timely manner.

8. The medical equipment remote control system based on Internet of Things data according to claim 7, characterized in that: Merge to form a temporary risk instruction data set, where the record contains at least the following fields: risk score S, risk level L, and emergency mark U; divide the records in the temporary risk instruction data set T4 into medium risk group and high risk group, and retain the value of U. If the record is an emergency scenario, mark it with an emergency priority mark; The key elements of each record are combined into a vector x = (S, L, U), and the following priority Π(x) is defined to evaluate the final strategy strength by integrating multi-dimensional features: Where: ||x|| p is the p-norm of x, usually p=2 to represent the Euclidean length, Used to gradually accumulate risk from 0 to ||x|| p The process is amplified, det(I+x T x) measures the synergistic lifting effect of each component of x, are all control coefficients greater than 0, and I is the unit matrix of the corresponding dimension.

9. The medical equipment remote control system based on Internet of Things data according to claim 8, characterized in that: After calculating the priority Π(x), compare the result with several predefined intervals. Use a lower level of protection, additional identity verification or warning reminders; if Follow a medium-intensity protection process, with high-intensity multi-factor authentication and approval processes; If the priority Follow the high-intensity protection process, temporarily freeze operations, force secondary approval, or allow operations in emergency scenarios but conduct full-process video recording and auditing; write the final priority Π(x) of each record and the selected strategy mapping result into the strategy mapping output object.

Citation Information

Patent Citations

  • A medical equipment remote control method and system

    CN118534832B

  • Adverse drug reaction trace management method and system

    CN118280602A